- Location
- Cebu City
- Type
- Full-time
- Education
- Bachelor
- Closing date
- Today
- Source
- CareersPage
Description
The SOC Analyst II is responsible for monitoring, investigating, and responding to cybersecurity threats and incidents across the organization's environment. This role serves as an escalation point for complex security events and helps strengthen the organization's security posture through threat detection, incident response, threat hunting, and continuous improvement of security processes.
Job Responsibilities:
- Monitor and investigate security alerts from Microsoft Defender XDR, Wazuh, Microsoft
Entra ID, Microsoft Purview, Keeper, and other security tools. - Analyze and respond to security incidents, including phishing attacks, malware infections, account compromises, unauthorized access attempts, and suspicious activities.
- Perform threat hunting activities to proactively identify potential threats and indicators of compromise.
- Lead incident response activities, including containment, eradication, recovery, and root cause analysis.
- Investigate identity and access-related security events within Microsoft Entra ID, including suspicious sign-ins, privileged access activities, and account takeover attempts.
- Monitor and respond to data protection and Data Loss Prevention (DLP) alerts through Microsoft Purview.
- Support vulnerability management efforts by validating findings and coordinating remediation with system owners.
- Develop and improve detection rules, alert tuning, investigation procedures, and security monitoring processes.
- Document incidents, investigations, findings, and recommendations in accordance with established procedures.
- Prepare security reports and provide updates to management and relevant stakeholders.
- Support security audits, compliance assessments, and customer requirements using platforms such as Vanta.
- Provide technical guidance and mentoring to SOC Analyst I team members.
- Collaborate with IT, Security, Compliance, and business teams to improve security controls and operational effectiveness.
- Recommend and implement enhancements to security technologies, processes, and SOC operations.
Job Qualifications:
- Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Two (2) to four (4) years of experience in Security Operations, Incident Response, or Cybersecurity.
- Experience with SIEM, EDR, XDR, and security monitoring platforms.
- Strong understanding of: Incident Response Threat Detection and Analysis Network Security Identity and Access Management Vulnerability Management Knowledge of the MITRE ATT&CK Framework.
- Preferred Experience with: Microsoft Sentinel/Wazuh Microsoft Defender XDR Microsoft Entra ID Azure Security Services
Skills
AzureCybersecuritySIEMSOCComplianceLoss Prevention